package com.itheima.controller;

import org.springframework.security.access.annotation.Secured;
import org.springframework.stereotype.Controller;
import org.springframework.web.bind.annotation.RequestMapping;

@Controller
@RequestMapping("/product")
public class ProductController {
    //@PreAuthorize("hasAnyAuthority('ROLE_ADMIN',ROLE_PRODUCT)")
    //@RolesAllowed({"ROLE_ADMIN","ROLE_PRODUCT"})//jsr250注解
    @Secured({"ROLE_ADMIN","ROLE_PRODUCT"})//security注解
    @RequestMapping("/findAll")
    public String findAll(){
        return "product-list";
    }
}
